
0xdf
@0xdf_
Training Architect @ HackTheBox
"Potentially a legit security researcher"
he/him
youtube.com/c/0xdf0xdf
0xdf.bsky.social
0xdf on discord
ID: 2980607794
https://0xdf.gitlab.io 16-01-2015 01:57:29
2,2K Tweet
23,23K Followers
448 Following

BigBang from Hack The Box starts off with a very tricky vuln chaining a file read in a WordPress plugin to a buffer overflow in Glibc to get RCE. Then there's Grafana and an Android APK. 0xdf.gitlab.io/2025/05/03/htb…



Underpass from Hack The Box has SNMP enumeration, daloRADIUS exploitation, and mobile shell (or mosh) abuse. 0xdf.gitlab.io/2025/05/10/htb…

In Heal from Hack The Box, I'll find a file read to get a rails config / database. I'll get into a LineSurvey instance and make a malicious plugin to get RCE. I'll abuse an insecure Consul instance to root. Beyond Root, an SSRF that didn't work. 0xdf.gitlab.io/2025/05/17/htb…

Email from 0xSirius and Artu about a neat find on the Heal box from Hack The Box. They used /proc file descriptors to read the database directly from the file read / directory traversal in the website, rather than pull the SQLite db. Let's explore. youtube.com/watch?v=BZnqip…

EscapeTwo from Hack The Box is a Windows box with MSSQL, some AD, and ESC4. 0xdf.gitlab.io/2025/05/24/htb…



Checker from Hack The Box has some really complex exploitation steps. There's SQLI in Teampass, SSRF to file read in BookStack using a blind PHP filter oracle, and shared memory abuse. 0xdf.gitlab.io/2025/05/31/htb…



Just released five videos showing four retired very easy coding challenges from Hack The Box, as well as a 5th video showing how to write your own script to submit skipping the web IDE. Hopefully more beginner oriented. youtube.com/watch?v=OC5J9y…


Backfire from Hack The Box is all about exploiting C2s. The most fun was chaining an SSRF with a command injection to get RCE, writing my own code to open a websocket via the SSRF. I'll exploit both Havoc and HardHatC2. 0xdf.gitlab.io/2025/06/07/htb…

Triple Knock is another coding challenge from the Hack The Box Biz CTF in May. This is all about parsing data into a way that's usable. I'll use a simple class to handle the parsing and make the data necessary available. Still beginner friendly. youtube.com/watch?v=3iRXRU…

Today’s a good day to recommend this exceptional book by Kim Zetter: Countdown to Zero Day. Easily in my top 2 cybersecurity books, right after The Cuckoo’s Egg by Clifford Stoll. There’s even an audiobook version for your next commute or evening walk. Amazon 📘


Infiltrator from Hack The Box has a ton. There's a lot of exploitation of Output Messenger. There's AD, ADCS, password spray. I learned some interesting bits about changing user's passwords as well. 0xdf.gitlab.io/2025/06/14/htb…

If you are doing any kind of ADCS enumeration / exploitation, I cannot understate how good and useful the Certipy wiki it. Huge shoutout to Oliver Lyak and the other contributors for this resource. github.com/ly4k/Certipy/w…
